Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-57497 Vulnerability in github.com/quic-go/webtransport-go (CVE-2026-57497)
vulnerability in github.com/quic-go/webtransport-go (CVE-2026-57497). Risk of unauthorized operations or information disclosure. Exploitable via ``io.ReadAll``. Mitigation: upgrade to `0.11.1` or later.
CVE-2026-55502 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502). Data can be tampered with by attackers. Exploitable via `POST /api/v4/admin/policy/oauth/signin`. Mitigation: upgrade to `4.17.0` or later.
CVE-2026-55499 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55499)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55499). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/file/events`. Mitigation: upgrade to `4.0.0-20260613030215-0b00dd308f13` or later.
CVE-2026-55497 Vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55497)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55497). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v4/user/setting/avatar`. Mitigation: upgrade to `4.0.0-20260613024411-3607f79bb44c` or later.
CVE-2026-55496 Information Disclosure in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55496)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55496). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/user/search`. Mitigation: upgrade to `4.0.0-20260613023921-7e1289d55279` or later.
CVE-2026-55495 Path Traversal in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55495)
path traversal in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55495). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v4/file/wopi/`. Mitigation: upgrade to `4.0.0-20260613023150-7968e50429ef` or later.
CVE-2026-66041 FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
CVE-2026-66040 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
CVE-2026-66039 FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
CVE-2026-66038 Vulnerability in c (CVE-2026-66038)
vulnerability in c (CVE-2026-66038). Confidential information can be exposed externally.
CVE-2026-66037 Vulnerability in c (CVE-2026-66037)
vulnerability in c (CVE-2026-66037). Risk of unauthorized operations or information disclosure.
CVE-2026-66036 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
CVE-2026-62835 Vulnerability in microsoft (CVE-2026-62835)
vulnerability in microsoft (CVE-2026-62835). Confidential information can be exposed externally.
CVE-2026-57531 Cross-Site Scripting (XSS) in CVE-2026-57531 (CVE-2026-57531)
cross-site scripting in CVE-2026-57531 (CVE-2026-57531). Risk of unauthorized operations or information disclosure.
CVE-2026-57530 Cross-Site Scripting (XSS) in CVE-2026-57530 (CVE-2026-57530)
cross-site scripting in CVE-2026-57530 (CVE-2026-57530). Risk of unauthorized operations or information disclosure.
CVE-2026-54342 Vulnerability in CVE-2026-54342 (CVE-2026-54342)
vulnerability in CVE-2026-54342 (CVE-2026-54342). Confidential information can be exposed externally.
CVE-2026-48021 Vulnerability in CVE-2026-48021 (CVE-2026-48021)
vulnerability in CVE-2026-48021 (CVE-2026-48021). Confidential information can be exposed externally.
CVE-2026-17107 Vulnerability in CVE-2026-17107 (CVE-2026-17107)
vulnerability in CVE-2026-17107 (CVE-2026-17107). Successful exploitation can lead to full system takeover.
CVE-2026-66035 Vulnerability in c (CVE-2026-66035)
vulnerability in c (CVE-2026-66035). Successful exploitation can lead to full system takeover.
CVE-2026-66034 Out-of-Bounds Read in libssh2 (CVE-2026-66034)
vulnerability in libssh2 (CVE-2026-66034). Successful exploitation can lead to full system takeover.
CVE-2026-66033 Out-of-Bounds Read in c (CVE-2026-66033)
vulnerability in c (CVE-2026-66033). Risk of unauthorized operations or information disclosure.
CVE-2026-66032 Vulnerability in c (CVE-2026-66032)
vulnerability in c (CVE-2026-66032). Successful exploitation can lead to full system takeover.
CVE-2026-65711 OS Command Injection in CVE-2026-65711 (CVE-2026-65711)
OS command injection in CVE-2026-65711 (CVE-2026-65711). Successful exploitation can lead to full system takeover.
CVE-2026-65710 Vulnerability in CVE-2026-65710 (CVE-2026-65710)
vulnerability in CVE-2026-65710 (CVE-2026-65710). Confidential information can be exposed externally.
CVE-2026-65709 Vulnerability in CVE-2026-65709 (CVE-2026-65709)
vulnerability in CVE-2026-65709 (CVE-2026-65709). Confidential information can be exposed externally.
CVE-2026-65708 Vulnerability in CVE-2026-65708 (CVE-2026-65708)
vulnerability in CVE-2026-65708 (CVE-2026-65708). Confidential information can be exposed externally.
CVE-2026-65707 SQL Injection in sqli (CVE-2026-65707)
SQL injection in sqli (CVE-2026-65707). Confidential information can be exposed externally.
CVE-2026-65623 Vulnerability in dos (CVE-2026-65623)
vulnerability in dos (CVE-2026-65623). Risk of unauthorized operations or information disclosure.
CVE-2026-59714 Vulnerability in open-webui (CVE-2026-59714)
vulnerability in open-webui (CVE-2026-59714). Data can be tampered with by attackers. Exploitable via `POST /api/chat/completions`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-73507 Vulnerability in io.netty:netty-codec-xml (CVE-2026-73507)
vulnerability in io.netty:netty-codec-xml (CVE-2026-73507). Risk of unauthorized operations or information disclosure. Exploitable via ``maxFrameLength``. Mitigation: upgrade to `4.1.136.Final` or later.
CVE-2026-73508 Vulnerability in io.netty:netty-codec-dns (CVE-2026-73508)
vulnerability in io.netty:netty-codec-dns (CVE-2026-73508). Risk of unauthorized operations or information disclosure. Exploitable via ``IDN.toASCII``. Mitigation: upgrade to `4.1.136.Final` or later.
GHSA-r277-6w6q-xmqw Authentication Bypass in github.com/getkin/kin-openapi (GHSA-r277-6w6q-xmqw)
authentication bypass in github.com/getkin/kin-openapi (GHSA-r277-6w6q-xmqw). Risk of unauthorized operations or information disclosure. Exploitable via `GET /secret`. Mitigation: upgrade to `0.144.0` or later.
GHSA-gcjh-h69q-9w9g Vulnerability in github.com/google/cel-go (GHSA-gcjh-h69q-9w9g)
vulnerability in github.com/google/cel-go (GHSA-gcjh-h69q-9w9g). Risk of unauthorized operations or information disclosure. Exploitable via ``newNativeTypes``. Mitigation: upgrade to `0.29.0` or later.
CVE-2026-73643 Vulnerability in js-yaml (CVE-2026-73643)
vulnerability in js-yaml (CVE-2026-73643). Risk of unauthorized operations or information disclosure. Exploitable via ``maxDepth``. Mitigation: upgrade to `5.2.2` or later.
CVE-2026-73429 Vulnerability in russh (CVE-2026-73429)
vulnerability in russh (CVE-2026-73429). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.62.4` or later.
CVE-2026-73489 Vulnerability in russh (CVE-2026-73489)
vulnerability in russh (CVE-2026-73489). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.0` or later.
CVE-2026-73430 Vulnerability in russh (CVE-2026-73430)
vulnerability in russh (CVE-2026-73430). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.62.4` or later.
GHSA-qwww-vcr4-c8h2 Cross-Site Request Forgery (CSRF) in react-router (GHSA-qwww-vcr4-c8h2)
vulnerability in react-router (GHSA-qwww-vcr4-c8h2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.3.0` or later.
GHSA-464c-974j-9xm6 Vulnerability in aws-cdk-lib (GHSA-464c-974j-9xm6)
vulnerability in aws-cdk-lib (GHSA-464c-974j-9xm6). Risk of unauthorized operations or information disclosure. Exploitable via ``S3LoggingOptions``. Mitigation: upgrade to `2.253.0` or later.
GHSA-r9mr-m37c-5fr3 OS Command Injection in GitPython (GHSA-r9mr-m37c-5fr3)
OS command injection in GitPython (GHSA-r9mr-m37c-5fr3). Risk of unauthorized operations or information disclosure. Exploitable via ``check_unsafe_options``. Mitigation: upgrade to `3.1.54` or later.
GHSA-6p8h-3wgx-97gf OS Command Injection in GitPython (GHSA-6p8h-3wgx-97gf)
OS command injection in GitPython (GHSA-6p8h-3wgx-97gf). Risk of unauthorized operations or information disclosure. Exploitable via ``unsafe_git_clone_options``. Mitigation: upgrade to `3.1.54` or later.
GHSA-fjr4-x663-mwxc Vulnerability in GitPython (GHSA-fjr4-x663-mwxc)
vulnerability in GitPython (GHSA-fjr4-x663-mwxc). Risk of unauthorized operations or information disclosure. Exploitable via ``diff``. Mitigation: upgrade to `3.1.54` or later.
GHSA-r292-9mhp-454m Vulnerability in tar (GHSA-r292-9mhp-454m)
vulnerability in tar (GHSA-r292-9mhp-454m). Risk of unauthorized operations or information disclosure. Exploitable via ``tar``. Mitigation: upgrade to `7.5.21` or later.
CVE-2026-73646 Path Traversal in postcss (CVE-2026-73646)
path traversal in postcss (CVE-2026-73646). Confidential information can be exposed externally. Exploitable via ``loadFile``. Mitigation: upgrade to `8.5.18` or later.
GHSA-w28w-gp39-m4p6 Code Injection in @prompty/core (GHSA-w28w-gp39-m4p6)
code injection in @prompty/core (GHSA-w28w-gp39-m4p6). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0-beta.5` or later.
CVE-2026-73562 Vulnerability in mongoose (CVE-2026-73562)
vulnerability in mongoose (CVE-2026-73562). Risk of unauthorized operations or information disclosure. Exploitable via ``Object.prototype``. Mitigation: upgrade to `9.7.2` or later.
GHSA-3rp5-jjmw-4wv2 Vulnerability in gitpython (GHSA-3rp5-jjmw-4wv2)
vulnerability in gitpython (GHSA-3rp5-jjmw-4wv2). Risk of unauthorized operations or information disclosure. Exploitable via ``core.sshCommand``. Mitigation: upgrade to `3.1.50` or later.
CVE-2026-73649 Code Injection in velocityjs (CVE-2026-73649)
code injection in velocityjs (CVE-2026-73649). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.7` or later.
CVE-2026-73563 Open Redirect in @backstage/plugin-auth-backend (CVE-2026-73563)
vulnerability in @backstage/plugin-auth-backend (CVE-2026-73563). Risk of unauthorized operations or information disclosure. Exploitable via ``allowedClientIdPatterns``. Mitigation: upgrade to `0.29.2` or later.
CVE-2026-62946 Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-62946)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-62946). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.15.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →